Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 195

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Apple picks Google's Gemini to run AI-powered Siri coming this year
Novo Nordisk CEO explains why new GLP-1 pill expands access to the weight loss drugs
Discount grocer Aldi plans to open more than 180 stores in U.S. this year as customers across incomes seek value
Powell investigation: Drumbeat of Republican opposition grows on Capitol Hill
Bank of America boosts Micron price target, sees upside driven by tight memory supply
JPMorgan Chase tops estimates as trading revenue exceeds expectations
Trump says Microsoft will make changes to ensure consumers don't pay for power used in AI buildout
Does it really matter who ends up owning Warner Bros.? Media exec Tom Rogers breaks it down
Fanatics to launch sports media and entertainment studio
Salesforce releases updated Slackbot powered by Anthropic's AI model